Detects Outline instances running versions 0.86.0 through 1.5.x where the email OTP login flow has no attempt limit and the rate limiter is disabled by default. The rate limiter key can also be forged via unsigned JWT cookies, enabling unrestricted brute-force of the 6-digit OTP code within its 10-minute lifetime. Successful exploitation grants full account access including documents and admin controls.
Is your app exploitable through CVE-2026-33640?
Scan your domain free